In connsyslogger, there is a possible symbolic link following due to improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06335038; Issue ID: ALPS06335038.
References
Link | Resource |
---|---|
https://corp.mediatek.com/product-security-bulletin/March-2022 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2022-03-10 09:45
Updated : 2022-03-17 10:55
NVD link : CVE-2022-20050
Mitre link : CVE-2022-20050
JSON object : View
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
Products Affected
mediatek
- mt6779
- mt6795
- mt8735b
- mt8786
- mt6891
- mt8766
- mt6889
- mt8385
- mt8791
- mt8183
- mt8735a
- mt6877
- mt8667
- mt6781
- mt8765
- mt8365
- mt8666
- mt8797
- mt6762
- mt6765
- mt6797
- mt6799
- mt6785
- mt8789
- mt8163
- mt6853
- mt6768
- mt8167s
- mt8173
- mt8696
- mt6833
- mt6885
- mt6880
- mt6883
- mt8321
- mt8788
- mt6893
- mt6769
- mt8362a
- mt6873
- mt8168
- mt8175
- mt8768
- mt6853t
- mt8167
- mt8675
- mt6875
- mt8185
- android